WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,851–7,900 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 158 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium IP Based Login Plugin ip-based-login Cross-Site Scripting ≤ 2.4.2 Fixed in 2.4.3 CVE-2025-50016 Patchstack
5.9 Medium Simple Sticky Footer Plugin simple-sticky-footer Cross-Site Scripting ≤ 1.3.5 CVE-2025-50019 Patchstack
5.9 Medium Tealium Plugin tealium Cross-Site Scripting ≤ 2.1.20 Fixed in 2.1.21 CVE-2025-50018 Patchstack
5.9 Medium WP Voting Contest Plugin wp-voting-contest Cross-Site Scripting ≤ 5.8 CVE-2025-50017 Patchstack
5.9 Medium Better Random Redirect Plugin better-random-redirect Cross-Site Scripting ≤ 1.3.20 CVE-2025-50021 Patchstack
5.9 Medium RDFa Breadcrumb Plugin rdfa-breadcrumb Cross-Site Scripting ≤ 2.3 CVE-2025-50020 Patchstack
5.9 Medium CodePen Embed Block Plugin codepen-embed-block Cross-Site Scripting ≤ 1.2.0 CVE-2025-50023 Patchstack
5.9 Medium WP-FB-AutoConnect Plugin wp-fb-autoconnect Cross-Site Scripting ≤ 4.6.4 CVE-2025-50022 Patchstack
5.9 Medium CP Polls Plugin cp-polls Cross-Site Scripting ≤ 1.0.81 Fixed in 1.0.82 CVE-2025-50025 Patchstack
5.9 Medium ATP Call Now Plugin atp-call-now Cross-Site Scripting ≤ 1.0.3 CVE-2025-50024 Patchstack
5.9 Medium Login/Signup Popup Plugin easy-login-woocommerce Cross-Site Scripting ≤ 2.9.4 Fixed in 2.9.5 CVE-2025-50027 Patchstack
5.9 Medium Spoki Plugin spoki Cross-Site Scripting ≤ 2.17.0 CVE-2025-50026 Patchstack
6.5 Medium Fitness Park Plugin fitness-park Cross-Site Scripting ≤ 1.1.1 CVE-2025-50033 Patchstack
6.5 Medium Spark Multipurpose Plugin spark-multipurpose Cross-Site Scripting ≤ 1.0.7 CVE-2025-50030 Patchstack
6.5 Medium Fyrebox Quizzes Plugin fyrebox-shortcode Cross-Site Scripting ≤ 3.1 CVE-2025-50035 Patchstack
6.5 Medium Enhanced Blocks – Page Builder Blocks for Gutenberg Plugin enhanced-blocks Broken Access Control Page Builder Blocks for Gutenberg plugin <= 1.4.1 - Broken Access Control ≤ 1.4.1 CVE-2025-50034 Patchstack
6.5 Medium Buying Buddy IDX CRM Plugin buying-buddy-idx-crm Cross-Site Scripting ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-50037 Patchstack
6.5 Medium Mailing Group Listserv Plugin wp-mailing-group Cross-Site Request Forgery No login needed ≤ 3.0.5 CVE-2025-50036 Patchstack
6.5 Medium WP Register Profile With Shortcode Plugin wp-register-profile-with-shortcode Cross-Site Scripting ≤ 3.6.3 CVE-2025-50042 Patchstack
6.5 Medium Gutenberg Blocks – ACF Blocks Suite Plugin acf-blocks Cross-Site Scripting ACF Blocks Suite plugin <= 2.6.11 - Cross Site Scripting (XSS) ≤ 2.6.11 CVE-2025-50041 Patchstack
6.5 Medium Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Scripting ≤ 1.2.8 CVE-2025-50038 Patchstack
6.5 Medium Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-50044 Patchstack
6.5 Medium Code Engine Plugin code-engine Cross-Site Scripting ≤ 0.3.2 Fixed in 0.3.3 CVE-2025-50043 Patchstack
6.5 Medium WPComplete Plugin wpcomplete Cross-Site Scripting ≤ 2.9.5 Fixed in 2.9.5.1 CVE-2025-50046 Patchstack
6.5 Medium Related Products Manager for WooCommerce Plugin related-products-manager-woocommerce Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-50045 Patchstack
6.5 Medium Automatically Hierarchic Categories in Menu Plugin automatically-hierarchic-categories-in-menu Cross-Site Scripting ≤ 2.0.9 Fixed in 2.0.10 CVE-2025-50048 Patchstack
6.5 Medium Sitekit Plugin sitekit Cross-Site Scripting ≤ 1.9 Fixed in 2.0 CVE-2025-50047 Patchstack
6.5 Medium Jobs Plugin job-postings Cross-Site Scripting ≤ 2.7.14 Fixed in 2.7.15 CVE-2025-50050 Patchstack
6.5 Medium Modern Footnotes Plugin modern-footnotes Cross-Site Scripting ≤ 1.4.19 Fixed in 1.4.20 CVE-2025-50049 Patchstack
7.1 High Virtual Moderator Plugin virtual-moderator Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-52772 Patchstack
6.5 Medium WP-Members Plugin wp-members Cross-Site Scripting ≤ 3.5.4 Fixed in 3.5.4.1 CVE-2025-50051 Patchstack
7.1 High TinyNav Plugin tinynav Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-52781 Patchstack
7.1 High Logo Manager For Samandehi Plugin samandehi-logo-manager Cross-Site Request Forgery No login needed ≤ 0.5 CVE-2025-52780 Patchstack
7.1 High Change Cart button Colors WooCommerce Plugin wc-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-52783 Patchstack
7.1 High Scroll UP Plugin scroll-to-up Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-52782 Patchstack
7.1 High Lewe ChordPress Plugin chordpress Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.1 CVE-2025-52789 Patchstack
7.1 High Bluff Post Plugin bluff-post Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-52784 Patchstack
7.1 High Knowledge Base – Knowledge Base Maker Plugin knowledge-base-maker Cross-Site Request Forgery Knowledge Base Maker plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2025-52791 Patchstack
7.1 High WP-DownloadCounter Plugin wp-downloadcounter Cross-Site Request Forgery No login needed ≤ 1.01 CVE-2025-52790 Patchstack
7.1 High Esselink.nu Settings Plugin esselinknu-settings Cross-Site Request Forgery No login needed ≤ 4.5 CVE-2025-52793 Patchstack
7.1 High WP User Stylesheet Switcher Plugin wp-user-stylesheet-switcher Cross-Site Request Forgery No login needed ≤ v2.2.0 CVE-2025-52792 Patchstack
7.1 High WP Front User Submit / Front Editor Plugin front-editor Cross-Site Request Forgery No login needed ≤ 5.0.6 CVE-2025-52795 Patchstack
7.1 High Creative Contact Form Plugin sexy-contact-form Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-52794 Patchstack
8.5 High Video List Manager Plugin video-list-manager SQL Injection ≤ 1.7 CVE-2025-52821 Patchstack
7.5 High Import YouTube videos as WP Posts Plugin import-youtube-videos-as-wp-post Broken Access Control No login needed ≤ 2.1 CVE-2025-52802 Patchstack
8.8 High Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-52825 Patchstack
8.5 High WP Roadmap Plugin wp-roadmap SQL Injection ≤ 2.1.3 Fixed in 2.2.0 CVE-2025-52822 Patchstack
6.5 Medium ANON::form embedded secure form Plugin anonform-embedded-secure-form Cross-Site Scripting ≤ 1.7 Fixed in 1.8 CVE-2025-52733 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Full Path Disclosure (FPD) ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-52719 Patchstack
7.5 High Classified Listing Plugin classified-listing Local File Inclusion ≤ 4.2.0 Fixed in 4.2.1 CVE-2025-52715 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only